Executive brief
SQL Server is a database management system used by organizations to store and manage critical business data. This vulnerability allows an authorized user to read sensitive information from memory that should not be accessible, potentially exposing confidential data across the network.
Technical details
An out-of-bounds read vulnerability exists in Microsoft SQL Server that enables information disclosure. The vulnerability requires authentication and network access to exploit. An attacker with valid SQL Server credentials can trigger the out-of-bounds read to access and exfiltrate sensitive data from server memory. The attack vector is network-based and does not require elevated privileges beyond standard database access.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed